STT GDC STATEMENT

STT GDC response to Bloomberg’s article

Feb 21, 2023
author logo
STT GDC
SHARE
Link copied!

On 21 February 2023, Bloomberg published a story 'Hackers Scored Corporate Giants' Logins for Asian Data Centers’ on their website reporting about a cybersecurity threat to ST Telemedia Global Data Centres’ customer service portals. 

We refute some of the characterisations in the story which are materially inaccurate and serve only to motivate future activities by threat actors within the critical digital infrastructure sector.

The published Bloomberg article is sensationally captioned with ‘such credentials in the wrong hands could be dangerous, experts say, potentially allowing physical access to data centers.’  We can say with complete certainty that any threat to our customer service portals has no bearing whatsoever on the physical security of our data centres.

STT GDC’s customer service portals are cloud-based SaaS applications hosted with third parties and have absolutely no logical or physical connection to our data centre infrastructure or any customer IT equipment.  These applications are primarily used by customers to initiate a service request (for example, book a delivery or request a cross connect). By design, these customer service portals do not contain any personal or business critical data.

On this we can be very certain: any purported stolen user credentials for our customer service portals do not pose risks for either our data centre operations nor our customer IT systems and data. Any such user credentials are no longer valid and have not been valid for some time. 

All our data centres remain fully operational and secure.  

We would like to reiterate that ensuring data protection and privacy is a critical tenet at STT GDC. We have in place robust measures with modern security architectures that are constantly being updated to keep ahead of the ever-evolving threat landscape of today’s digital society.

Acting with integrity and transparency is important to us. STT GDC provided Bloomberg with the following statement before their story was published:

 

  • ST Telemedia Global Data Centres (STT GDC) is a colocation services provider headquartered in Singapore, with a global platform of data centres spanning Singapore, UK, India, Thailand, South Korea, Indonesia, Japan and Philippines. We note for the avoidance of doubt that this statement does not purport to speak for GDS Holdings Limited (Nasdaq: GDS), an independently operated company.

 

  • Ensuring data protection and privacy is a critical tenet at STT GDC. We have in place robust systems with modern security architectures that are constantly being updated to keep ahead of the ever-evolving threat landscape of today’s digital society.

 

  • It is important to recognise that in our colocation business, our customers operate all of their own IT equipment. None of our IT systems interface in any manner with our customers’ IT equipment. Our IT systems do not have the ability to view or disrupt our customer’s IT operations which remain totally segregated.

 

  • The genesis of your reporting appears to date back to a threat report we received in 2021. In September 2021 we were notified of the circulation via the dark web of a purported list of user credentials for one of our IT systems. Our teams took immediate action then, including conducting internal investigations and commissioning external cybersecurity providers. No unauthorised access or data loss relating to that IT system was observed, and the application remains secure to this day. The IT system in question is a customer service ticketing tool, a third-party application hosted in the cloud, which has no connection to our other corporate systems nor any critical data centre infrastructure.

 

  • More recently in January 2023, we received notification of further threats to customer service portals in our India and Thailand regions. Our relevant teams have conducted detailed reviews of these notifications, and our investigations to date indicate that there has been no data loss or impact to any of these customer service portals.

 

  • In short, our data centres and services remain fully operational and secure. The purported cyber security threats to our customer service portals have not affected the operation of our data centres in any way. In any event, our critical infrastructure and the associated monitoring systems are completely segregated from all of these customer service applications. 

 

For the avoidance of doubt, the Bloomberg story also makes several references to GDS Holdings Limited (NASDAQ: GDS) which is an independently operated company in which we are a minority investor. This post does not purport to speak for GDS.
 

For media queries, please contact: corpcomms@sttelemediagdc.com

 

 

Featured News